LEGAL / LAST UPDATED 6 SEPTEMBER 2026
Security and vulnerability disclosure
We welcome responsible reports that help us protect Noviom Labs, our clients and visitors. This page explains how to report a suspected security vulnerability safely.
1. Reporting a vulnerability
Email [email protected] with a clear description, the affected URL or service, steps to reproduce the issue and its potential impact. Do not include passwords, access tokens or unnecessary personal information in ordinary email.
2. Responsible testing
Please make a good-faith effort to avoid privacy violations, disruption, data destruction and degradation of our services. Do not use denial-of-service testing, automated high-volume scanning, social engineering, physical attacks, malware, persistence or access to another person’s information. Stop testing and report the issue if you encounter personal, client or confidential data.
3. What you can expect
We aim to acknowledge a credible report within five working days, assess severity and keep the reporter informed when practical. Resolution time depends on complexity and risk. We may ask for additional information and may coordinate disclosure where this protects affected users.
4. Scope and rewards
This is a vulnerability disclosure process, not a bug-bounty programme, and we do not promise payment. It does not authorise access that would otherwise be unlawful or testing of third-party services. Reports about a supplier should normally be sent through that supplier’s disclosure process.
5. Security incidents and privacy
If you believe your own information has been affected, use the privacy contact in our privacy policy. Do not use this process for ordinary support or sales enquiries.